Viking Cipher

Cybersecurity News

Dark Reading

The Hackers News

KrebsOnSecurity

  • DOGE Worker’s Code Supports NLRB Whistleblower
    April 23, 2025

    A whistleblower at the National Labor Relations Board (NLRB) alleged last week that denizens of Elon Musk's Department of Government Efficiency (DOGE) siphoned gigabytes of data from the agency's sensitive case files in early March. The whistleblower said accounts created for DOGE at the N...

  • Whistleblower: DOGE Siphoned NLRB Case Data
    April 22, 2025

    A security architect with the National Labor Relations Board (NLRB) alleges that employees from Elon Musk's Department of Government Efficiency (DOGE) transferred gigabytes of sensitive data from agency case files in early March, using short-lived accounts configured to leave few traces of netw...

  • Funding Expires for Key Cyber Vulnerability Database
    April 16, 2025

    A critical resource that cybersecurity professionals worldwide rely on to identify, mitigate and fix security vulnerabilities in software and hardware is in danger of breaking down. The federally funded, non-profit research and development organization MITRE warned today that its contract to maintai...

  • Trump Revenge Tour Targets Cyber Leaders, Elections
    April 15, 2025

    President Trump last week revoked security clearances for Chris Krebs, the former director of the Cybersecurity and Infrastructure Security Agency (CISA) who was fired by Trump after declaring the 2020 election the most secure in U.S. history. The White House memo, which also suspended clearances fo...

  • China-based SMS Phishing Triad Pivots to Banks
    April 10, 2025

    China-based purveyors of SMS phishing kits are enjoying remarkable success converting phished payment card data into mobile wallets from Apple and Google. Until recently, the so-called “Smishing Triad” mainly impersonated toll road operators and shipping companies. But experts say these groups a...

  • Patch Tuesday, April 2025 Edition
    April 9, 2025

    Microsoft today released updates to plug at least 121 security holes in its Windows operating systems and software, including one vulnerability that is already being exploited in the wild. Eleven of those flaws earned Microsoft's most-dire "critical" rating, meaning malware or malcont...

  • Cyber Forensic Expert in 2,000+ Cases Faces FBI Probe
    April 4, 2025

    A Minnesota cybersecurity and computer forensics expert whose testimony has featured in thousands of courtroom trials over the past 30 years is facing questions about his credentials and an inquiry from the Federal Bureau of Investigation (FBI). Legal experts say the inquiry could be grounds to reop...

  • How Each Pillar of the 1st Amendment is Under Attack
    March 31, 2025

    In an address to Congress this month, President Trump claimed he had "brought free speech back to America." But barely two months into his second term, the president has waged an unprecedented attack on the First Amendment rights of journalists, students, universities, government workers, ...

  • When Getting Phished Puts You in Mortal Danger
    March 27, 2025

    Many successful phishing attacks result in a financial loss or malware infection. But falling for some phishing scams, like those currently targeting Russians searching online for organizations that are fighting the Kremlin war machine, can cost you your freedom or your life....

  • Arrests in Tap-to-Pay Scheme Powered by Phishing
    March 21, 2025

    Authorities in at least two U.S. states last week independently announced arrests of Chinese nationals accused of perpetrating a novel form of tap-to-pay fraud using mobile devices. Details released by authorities so far indicate the mobile wallets being used by the scammers were created through onl...

Wired (Security Section)

HackRead

CyberScoop

  • Cybersecurity experts issue response to Trump order targeting Chris Krebs, SentinelOne
    April 28, 2025

    The letter, released through the Electronic Frontier Foundation, calls Trump’s executive order “retaliatory.” The post Cybersecurity experts issue response to Trump order targeting Chris Krebs, SentinelOne appeared first on CyberScoop. ...

  • Cybersecurity vendors are themselves under attack by hackers, SentinelOne says
    April 28, 2025

    “It’s practically taboo” for cyber firms to talk about being targeted, but SentinelLabs said in a new report that it has observed multiple threats. The post Cybersecurity vendors are themselves under attack by hackers, SentinelOne says appeared first on CyberScoop. ...

  • House bill seeks better tech to combat financial fraud scams against elderly
    April 25, 2025

    The legislation calls on federal law enforcement to help state, local and tribal agencies with blockchain and other investigative tools to fight pig butchering and other schemes. The post House bill seeks better tech to combat financial fraud scams against elderly appeared first on CyberScoop. ...

  • SAP zero-day vulnerability under widespread active exploitation
    April 25, 2025

    Researchers attribute the attacks to an initial access broker who is exploiting the 10.0 critical vulnerability. The post SAP zero-day vulnerability under widespread active exploitation appeared first on CyberScoop. ...

  • CISA gets new No. 2: Madhu Gottumukkala
    April 24, 2025

    He served under then-South Dakota Gov. Kristi Noem, who now heads up the Department of Homeland Security. The post CISA gets new No. 2: Madhu Gottumukkala appeared first on CyberScoop. ...

  • VulnCheck spotted 159 actively exploited vulnerabilities in first few months of 2025
    April 24, 2025

    The vulnerability threat intelligence firm’s research reinforces a slew of recent reports warning about increased exploits in 2024. The post VulnCheck spotted 159 actively exploited vulnerabilities in first few months of 2025 appeared first on CyberScoop. ...

  • AI speeds up analysis work for humans, two federal cyber officials say
    April 24, 2025

    More broadly, AI is viewed as being a double-edged sword in cybersecurity, one that can bolster both defensive and offensive operations. The post AI speeds up analysis work for humans, two federal cyber officials say appeared first on CyberScoop. ...

  • Judge tosses citizenship provisions in Trump elections order
    April 24, 2025

    Requests to block federal agencies from sharing federal data with states and to condition federal election funding were denied by Judge Colleen Kollar-Kotelly. The post Judge tosses citizenship provisions in Trump elections order appeared first on CyberScoop. ...

  • Attackers hit security device defects hard in 2024
    April 23, 2025

    Mandiant said exploits were the most common initial access vector last year, linking software defects to 1 in 3 attacks. The most commonly exploited vulnerabilities affected network edge devices. The post Attackers hit security device defects hard in 2024 appeared first on CyberScoop. ...

  • 10 key numbers from the 2024 FBI IC3 report
    April 23, 2025

    The yearly report from the bureau is filled with stats. We pulled out the most interesting ones. The post 10 key numbers from the 2024 FBI IC3 report appeared first on CyberScoop. ...

Help Net Security

  • ArmorCode Anya accelerates critical security decisions
    April 28, 2025

    ArmorCode launched Anya, an agentic AI champion purpose-built for AppSec and product security teams. Following a successful early access program, Anya is now available to all ArmorCode enterprise customers, delivering intelligent, conversation-driven security insights that close the expertise gap an...

  • Palo Alto Networks Prisma AIRS safeguards the enterprise AI ecosystem
    April 28, 2025

    Palo Alto Networks announced Prisma AIRS, an AI security platform that serves as the cornerstone for AI protection, designed to protect the entire enterprise AI ecosystem – AI apps, agents, models, and data – at every step. Building upon the company’s Secure AI by Design portfolio laun...

  • AuditBoard AI governance solution mitigates risks associated with AI systems
    April 28, 2025

    AuditBoard announced a new AI governance solution, enableing customers to fast-track their AI risk management programs and drive responsible AI innovation and adoption at scale. AuditBoard’s new AI governance solution will help customers meet AI best practices outlined in frameworks like t...

  • Sentra Data Security for AI Agents protects AI-powered assistants
    April 28, 2025

    Sentra launched Data Security for AI Agents solution, specifically designed to address the emerging challenges associated with proliferating AI assistants and empower large enterprises to embrace AI innovation securely and responsibly. With the solution, Sentra also announced platform support for Ag...

  • Netskope One enhancements cover a broad range of AI security use cases
    April 28, 2025

    Netskope announced expansion of the Netskope One platform to cover more AI security use cases, including enhanced protections for private applications and data security posture management (DSPM) attributes. While other vendors focus on enabling safe user access to AI applications, Netskope capabilit...

  • Trend Micro helps organizations secure AI-driven workloads
    April 28, 2025

    Trend Micro announced new AI-powered threat detection capabilities designed specifically for enterprises embracing AI at scale. This effort brings together Trend’s security expertise with NVIDIA accelerated computing and NVIDIA AI Enterprise software, leveraging AWS infrastructure to suppo...

  • Censys enables security teams to be more proactive in their threat hunting
    April 28, 2025

    Censys is launching a new solution specifically designed to enable threat hunting teams to track adversary infrastructure. The Censys’ Threat Hunting solution is part of Censys’ recently released Internet Intelligence platform, which provides security teams across the enterprise ...

  • Abnormal AI improves security awareness training with AI agents
    April 28, 2025

    Abnormal AI introduces autonomous AI agents that improve how organizations train employees and report on risk while also evolving its email security capabilities. In a year defined by the explosive use of malicious AI for cybercrime, Abnormal is doubling down on its mission to protect people. With i...

  • Avocado OS: Open-source Linux platform for embedded systems
    April 28, 2025

    Peridio, a platform for building and maintaining advanced embedded products, has launched Avocado OS, an open-source embedded Linux distribution made to simplify the way developers build complex embedded systems. Avocado OS focuses on delivering a smooth developer experience while offering security,...

  • Flashpoint Ignite enhancements improve threat intelligence
    April 28, 2025

    Flashpoint announced new capabilities to its flagship platform, Flashpoint Ignite. These innovations are designed to deliver insights that align with customers’ threat intelligence needs, enabling organizations to make informed decisions and protect their most critical assets. “Too often...

ZDNet (Security Section)

Security Boulevard

  • Your NHIDR Is Getting Better—How?
    April 28, 2025

    Why Does Improving Non-Human Identity and Data Response (NHIDR) Matter? How often do we consider the impact of Non-Human Identities (NHIs) on our data security? The management of NHIs and their accompanying secrets has become an indispensable necessity for businesses. From financial services and hea...

  • Harnessing Powerful Tools for Secrets Scanning
    April 28, 2025

    Capturing the Essence of Powerful Secrets Scanning Wondering how to enhance your organization’s cybersecurity measures? Among the vast spectrum of cybersecurity tools available, secrets scanning is one that holds paramount significance. Secrets scanning, as an integral part of Non-Human Identities...

  • Certain Your Data Is Safe in the Cloud?
    April 28, 2025

    Are You Confident Your Data Safety Measures Are Up to Scratch? The rise of digital transformation is not without its pitfalls, one of which is the challenge of maintaining data safety and security. With the majority of businesses relying heavily on cloud-based environments for storing and handling d...

  • Bugcrowd Launches Red Team Service to Test Cybersecurity Defenses
    April 28, 2025

    Bugcrowd today at the 2025 RSA Conference announced its intent to create a red team service to test cybersecurity defenses using a global network of ethical hackers. Alistair Greaves, director of red team operations for Bugcrowd, said via a Red Team-as-a-Service (RTaaS) offering that a global pool ...

  • Blackpoint Cyber Extends MDR Service to Improve Cyber Resiliency
    April 28, 2025

    Blackpoint Cyber today at the 2025 RSA Conference unveiled a unified security posture and response platform that is based on the company’s managed detection and response (MDR) service. Company CTO Manoj Srivastava said the CompassOne platform provides organizations the tool to discover assets alo...

  • Anthropic Outlines How Bad Actors Abuse Its Claude AI Models
    April 28, 2025

    Anthropic shows how bad actors are using its Claude AI models for a range of campaigns that include influence-as-a-service, credential stuffing, and recruitment scams and becomes the latest AI company to push back at threat groups using their tools for malicious projects. The post Anthropic Outline...

  • Palo Alto Networks to Acquire Protect AI, Launches AI Security Platform
    April 28, 2025

    Accelerating its aggressive foray into artificial intelligence (AI) security, Palo Alto Networks Inc. on Monday said it has agreed to acquire cybersecurity startup Protect AI. Additionally, the company launched an ambitious AI security platform at the RSA Conference in San Francisco, as well as upd...

  • Best 12 PCI Compliance Solutions for Ensuring Compliance in 2025
    April 28, 2025

    No matter the size or industry, businesses that handle payment card data must comply with PCI DSS (Payment Card Industry Data Security Standard). However, not all businesses have the same compliance requirements. The scope and level of PCI compliance solutions depend on factors such as: Understandin...

  • BSides Seattle 2025: Rebuilding Trust in Systems In The Age Of NHIs
    April 28, 2025

    The BSides Seattle 2025 speakers showed how security and IAM fail under stress and why usable security must consider human limits and machine-scale risk. The post BSides Seattle 2025: Rebuilding Trust in Systems In The Age Of NHIs appeared first on Security Boulevard. ...

  • EU’s Chat Control Proposal: Balancing Child Protection and Digital Rights
    April 28, 2025

    The EU's Chat Control proposal presents a critical dilemma: protecting children from online abuse without compromising privacy and security. This comprehensive analysis decodes the legislation's technical implications and what it means for encrypted communications worldwide. The post EU&am...